Known vulnerabilities in nginx
Vendor:
Fedoraproject
Software:
nginx
Software CPE:
cpe:2.3:o:fedoraproject:nginx:*:*:*:*:*:fedora:*:*
Website:
https://getfedora.org/
Total vulnerabilities:
47
Public exploits:
7
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
1.30.4-1.fc45
1.30.3-1.fc43
1.30.3-1.fc44
1.30.3-1.fc45
1.30.2-2.fc45
1.30.2-1.fc43
1.30.2-1.fc44
1.30.1-1.fc42
1.30.1-1.fc43
1.30.1-1.fc44
1.28.3-1.fc44
1.28.2-1.fc42
1.28.2-1.fc43
1.16.1-2.el7
1.16.1-1.el7
1.16.1-1.fc29
mainline-3020190816153353.a5b0195c
mainline-2920190816153353.6c81f848
1.16.1-1.fc30
1.14.1-1.fc27
1.14.1-1.fc28
1.14.1-2.fc29
1.12.2-1.el7
1.12.1-1.fc26
1.12.1-1.fc25
1.10.1-1.el5
1.10.1-1.el6
1.6.3-9.el7
1.8.1-3.fc23
1.8.1-2.fc23
1.10.1-1.fc24
1.6.3-8.el7
1.8.1-1.fc22
1.8.1-1.fc23
0.8.55-6.el5
1.0.15-11.el6
1.0.15-10.el6
1.6.2-2.fc21
1.0.15-8.el6
1.6.2-1.el7
0.8.55-3.el5
1.0.15-4.el6
0.8.55-1.el5
1.26.3-1.fc40
1.26.3-1.fc41
1.26.3-1.fc42
1.20-3620221110171337.5e5ad4a0
1.20-3520221110171337.f27b74a8
1.20-3720221110171337.9e842022
1.20.1-10.el7
mainline-3720221019155610.9e842022
mainline-820220816123924.9edba152
mainline-3520221019155610.f27b74a8
mainline-3620221019155610.5e5ad4a0
1.22.1-1.fc37
1.22.1-1.fc35
1.22.1-1.fc36
1.20-3320210625014643.601d93de
1.20.1-3.fc34
1.20.1-3.fc33
1.20.1-2.fc34
1.20.1-2.el7
1.20.1-2.fc33
1.20.1-1.el7
1.20.1-1.fc34
1.20.1-1.fc33
1.20.0-2.fc32
1.20.0-2.fc34
1.20.0-2.fc33
1.26.2-1.fc39
1.26.2-1.fc40
mainline-3820240218193500.f38
1.0.15-1.el6
0.8.55-2.el5
1.0.14-1.el6
0.6.39-2.el5
0.6.39-1.el5
Vulnerabilities (47)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU137847 - Heap-based Buffer Overflow CVE-2026-42533 |
CWE-122 | High | 1.30.4-1.fc45 | 16.07.2026 |
SB2026071606 SB20260721112 SB20260721113 and 8 more |
||
| #VU137846 - Use of Uninitialized Resource CVE-2026-60005 |
CWE-908 | High | 1.30.4-1.fc45 | 16.07.2026 |
SB2026071606 SB20260721112 SB20260721113 and 9 more |
||
| #VU137845 - Use After Free CVE-2026-56434 |
CWE-416 | Medium | 1.30.4-1.fc45 | 16.07.2026 |
SB2026071606 SB20260721112 SB20260721113 and 9 more |
||
| #VU134864 - Out-of-bounds read CVE-2026-48142 |
CWE-125 | Medium | 1.30.3-1.fc43, 1.30.3-1.fc44, 1.30.3-1.fc45 | 18.06.2026 |
SB2026061844 SB2026061845 SB2026061846 and 10 more |
||
| #VU134863 - Use After Free CVE-2026-42530 |
CWE-416 | High | 1.30.3-1.fc43, 1.30.3-1.fc44, 1.30.3-1.fc45 | 18.06.2026 |
SB2026061844 SB2026061845 SB2026061846 and 2 more |
||
| #VU134861 - Heap-based Buffer Overflow CVE-2026-42055 |
CWE-122 | High | 1.30.3-1.fc43, 1.30.3-1.fc44, 1.30.3-1.fc45 | 18.06.2026 |
SB2026061844 SB2026061845 SB2026061846 and 12 more |
||
| #VU132220 - Heap-based Buffer Overflow CVE-2026-9256 |
CWE-122 | Critical | 1.30.2-1.fc43, 1.30.2-1.fc44 | 25.05.2026 |
SB2026052502 SB2026052504 SB2026052505 and 12 more |
||
| #VU131379 - Use After Free CVE-2026-40701 |
CWE-416 | Medium | 1.30.1-1.fc42, 1.30.1-1.fc43, 1.30.1-1.fc44 | 14.05.2026 |
SB2026051401 SB2026051497 SB2026051498 and 12 more |
||
| #VU131378 - Authentication Bypass by Spoofing CVE-2026-40460 |
CWE-290 | Medium | 1.30.1-1.fc42, 1.30.1-1.fc43, 1.30.1-1.fc44 | 14.05.2026 |
SB2026051401 SB2026051497 SB2026051498 and 4 more |
||
| #VU131377 - Heap-based Buffer Overflow CVE-2026-42945 |
CWE-122 | Critical | 1.30.1-1.fc42, 1.30.1-1.fc43, 1.30.1-1.fc44 | 14.05.2026 |
SB2026051401 SB2026051497 SB2026051498 and 26 more |
||
| #VU131376 - CVE-2026-42926 |
Medium | 1.30.1-1.fc42, 1.30.1-1.fc43, 1.30.1-1.fc44 | 14.05.2026 |
SB2026051401 SB2026051497 SB2026051498 and 1 more |
|||
| #VU131375 - Uncontrolled Memory Allocation CVE-2026-42946 |
CWE-789 | Medium | 1.30.1-1.fc42, 1.30.1-1.fc43, 1.30.1-1.fc44 | 14.05.2026 |
SB2026051401 SB2026051497 SB2026051498 and 14 more |
||
| #VU131374 - Out-of-bounds read CVE-2026-42934 |
CWE-125 | Medium | 1.30.1-1.fc42, 1.30.1-1.fc43, 1.30.1-1.fc44 | 14.05.2026 |
SB2026051401 SB2026051497 SB2026051498 and 12 more |
||
| #VU124482 - Improper Neutralization of CRLF Sequences ('CRLF Injection') CVE-2026-28753 |
CWE-93 | Medium | 1.28.3-1.fc44 | 25.03.2026 |
SB2026032585 SB20260325200 SB2026041117 and 4 more |
||
| #VU124480 - Integer overflow CVE-2026-27784 |
CWE-190 | High | 1.28.3-1.fc44 | 25.03.2026 |
SB2026032585 SB20260325200 SB2026040801 and 17 more |
||
| #VU124478 - Heap-based Buffer Overflow CVE-2026-27654 |
CWE-122 | Medium | 1.28.3-1.fc44 | 25.03.2026 |
SB2026032585 SB20260325200 SB2026033174 and 17 more |
||
| #VU124475 - Out-of-bounds write CVE-2026-32647 |
CWE-787 | High | 1.28.3-1.fc44 | 25.03.2026 |
SB2026032585 SB20260325200 SB2026040801 and 17 more |
||
| #VU124473 - NULL Pointer Dereference CVE-2026-27651 |
CWE-476 | Medium | 1.28.3-1.fc44 | 25.03.2026 |
SB2026032585 SB20260325200 SB2026040801 and 17 more |
||
| #VU124470 - Incorrect Authorization CVE-2026-28755 |
CWE-863 | Medium | 1.28.3-1.fc44 | 25.03.2026 |
SB2026032585 SB20260325200 SB2026081734 |
||
| #VU122335 - Acceptance of Extraneous Untrusted Data With Trusted Data CVE-2026-1642 |
CWE-349 | Medium | 1.28.2-1.fc42, 1.28.2-1.fc43 | 05.02.2026 |
SB2026020501 SB2026020505 SB2026020511 and 22 more |
Showing elements 1 - 20 out of 47